PT-2024-29030 · Openstack+2 · Openstack Nova+2

·

CVE-2024-40767

·

Published

2024-07-23

·

Updated

2026-07-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Nova versions prior to 29.1.1
Description A medium severity issue affects OpenStack Nova, where crafted image paths can expose sensitive data, potentially leading to data theft risk.
Recommendations For OpenStack Nova versions prior to 29.1.1, update to version 29.1.1 or later to resolve the issue.

Exploit

Fix

DoS

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-40767
DLA-3873-1
GHSA-RM86-H44C-2R2M
PYSEC-2026-1709
RHSA-2024:5083
RHSA-2024:5097
RHSA-2024:5113
USN-6911-1

Affected Products

Linuxmint
Openstack Nova
Ubuntu